CISA Known Exploited Vulnerability

CVE-2020-1054

Microsoft · Win32k

Microsoft Win32k Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-787
Ransomware Unknown

CISA description

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

Required action

Apply updates per vendor instructions.